$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Grav CMS 1.7.10 boot2root box. Solution: fuzz an encrypted ZIP, crack it with zip2john to get admin creds, exploit authenticated Grav Twig SSTI (CVE-2021-29440) for RCE, crack a PGP private-key passphrase with gpg2john and decrypt a message to pivot to user gravman, then escalate to root via Python library hijacking (local random.py) of a NOPASSWD sudo script.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar